• Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization.
• Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements.
• Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization’s compliance, certification, and internal and external audit activities.
• Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements.
• Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence.
• Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change.
• Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education.
• Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors.
• Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners.
• Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials.
• Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements.
• Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation.
• Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, OneDrive, SharePoint, and Teams.
• Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications.
• Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters.
• Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities.
• Support internal and external audits by gathering and producing evidence associated with cybersecurity awareness, training, Legal Hold, eDiscovery, and assigned security controls.
• Analyze cybersecurity compliance data and develop metrics that identify risks, demonstrate control effectiveness, and support continuous improvement.